Go Phish
Phishing simulation toolkit for security awareness training. Track who clicks and reports.
Open the official app on getgophish.com
This tool is hosted by its maintainers. Click below to open getgophish.com in a new tab — it's their official demo.
Browse security tools →What's next with Go Phish?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Go Phish?
Gophish is an open-source phishing framework designed to help organizations assess their vulnerability to phishing attacks. By simulating real-world phishing scenarios, it enables security teams to evaluate how employees respond to social engineering tactics. The tool is widely used by cybersecurity professionals, internal auditors, and incident response teams to strengthen organizational defenses. It addresses the critical problem of identifying weak points in human behavior and email security protocols, which are common entry points for cyberattacks. Gophish streamlines phishing testing by providing a user-friendly interface, customizable templates, and real-time analytics. Its MIT license allows free use and modification, making it accessible for both small businesses and large enterprises. The tool’s emphasis on practical, actionable insights helps organizations prioritize training and policy improvements.
How it works
Gophish is a phishing simulation tool that allows users to create and execute targeted phishing campaigns to test employee awareness and system resilience. It serves as a controlled environment for security teams to identify weaknesses in their organization’s defenses without compromising real data. The primary purpose of Gophish is to provide actionable insights into how phishing attacks might succeed within an organization. By mimicking real-world attack vectors, it helps teams refine training programs and improve email security protocols. Gophish enables users to design custom phishing templates using an integrated HTML editor, import existing email designs, and track recipient interactions in real time. It supports scheduling campaigns, monitoring email opens, and capturing link clicks or credential submissions. The tool’s REST API facilitates automation and integration with other security systems.
How to use it
- 1Download and install Gophish from its repository. 2. Configure the tool by setting up SMTP servers and defining target lists. 3. Create or import phishing templates using the HTML editor. 4. Launch the campaign and monitor results through the web interface. Practical tips include leveraging the REST API for automation and testing multiple scenarios simultaneously. Users should ensure email servers are properly configured and test campaigns in isolated environments to avoid unintended consequences.
What it can do
- phishing simulation
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/gophish/gophish
- license: MIT — free to use
- privacy: Self-hosted — you control your data
Limitations
- Offensive tool — authorized penetration testing and lab use only; unauthorized use is illegal.
- Limited advanced analytics compared to commercial phishing platforms
- Dependence on internal email infrastructure for campaign delivery
- Manual configuration required for complex email tracking scenarios
- No built-in database of real-world phishing templates
Understanding the result
Phishing simulation toolkit for security awareness training. Track who clicks and reports.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (gophish/gophish)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with gophish/gophish. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- MIT License
Upstream project
Frequently asked
What is GoPhish and how does it differ from other phishing tools?
Gophish is an open-source phishing framework focused on simplicity and customization. Unlike commercial tools, it lacks pre-built templates and advanced analytics but offers full control over campaign design. It differs from tools like Metaphor or CPHish by prioritizing lightweight deployment and integration with existing email systems.
How does Gophish handle email tracking and data collection?
Gophish uses webhooks and JavaScript-based tracking to monitor email opens and link clicks. When a recipient interacts with a phishing email, the tool records the event through the recipient’s browser. Credential submission is captured via form POST requests, which are logged by the server. All data is stored locally unless configured otherwise.
How do I create a phishing campaign with Gophish?
First, configure the SMTP settings in the Gophish dashboard. Next, use the HTML editor to design a phishing template or import an existing email. Define target recipients in a CSV file and map variables like sender names or links. Finally, schedule the campaign or launch it immediately, then monitor results through the real-time dashboard.
How does Gophish compare to commercial phishing platforms like PhishSim?
Gophish offers greater flexibility for customization but lacks the enterprise-grade features of PhishSim, such as automated reporting, advanced analytics, and integration with SIEM systems. Commercial tools often include pre-built templates and compliance-focused workflows, whereas Gophish requires manual setup and relies on user expertise for campaign design.
What should I do if Gophish fails to connect to my email server?
Verify that the SMTP settings in Gophish match your email server’s configuration, including port numbers and authentication credentials. Check for firewall rules blocking outgoing connections on the required port. If issues persist, enable debug logging in Gophish to identify specific connection errors.